Vulnerabilities in Liferay

210 results
Vexday analysis

O portfólio de vulnerabilidades do Liferay acumula 210 CVEs catalogadas, das quais 23 são de severidade crítica e 3 contam com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros ativos no catálogo CISA KEV. A taxa de exploração ativa de 0,0% posiciona o vendor abaixo da média geral do catálogo, o que representa um indicador positivo, mas não elimina a necessidade de atenção às falhas críticas existentes. O tipo de falha mais prevalente é CWE-79 (Cross-Site Scripting), historicamente associado a ataques de injeção de conteúdo em aplicações web, como portais corporativos — segmento central no ecossistema Liferay. A CVE mais perigosa em observação no momento é CVE-2025-4388, com escore EPSS de 0,0345, sinalizando probabilidade ainda baixa de exploração em larga escala, mas que deve ser monitorada dado o contexto recente de sua catalogação.

CVE-2025-43740MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, EPSS 0.2%CVE-2025-62265MEDIUMCross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and EPSS 0.2%CVE-2025-43757MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.QEPSS 0.2%CVE-2025-43821MEDIUMCross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and LifeEPSS 0.2%CVE-2025-43822MEDIUMMultiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2EPSS 0.2%CVE-2025-62240MEDIUMMultiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.EPSS 0.2%CVE-2025-43755MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 20EPSS 0.2%CVE-2025-62237MEDIUMStored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2EPSS 0.2%CVE-2025-43829MEDIUMStored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and LiferEPSS 0.2%CVE-2025-62246MEDIUMMultiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and LiEPSS 0.2%CVE-2025-43746MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.QEPSS 0.2%CVE-2025-62238MEDIUMStored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, andEPSS 0.2%CVE-2025-43776MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 202EPSS 0.2%CVE-2025-43775MEDIUMStored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024EPSS 0.2%CVE-2025-43823MEDIUMCross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 202EPSS 0.2%CVE-2025-43734MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.2%CVE-2025-43817MEDIUMMultiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 througEPSS 0.2%CVE-2025-43731MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.2%CVE-2025-43756MEDIUM<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerability in the Liferay EPSS 0.2%CVE-2025-43747MEDIUMA server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation oEPSS 0.2%